Описание
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.
Ссылки
- Third Party Advisory
- ExploitRelease NotesVendor Advisory
- Third Party Advisory
- ExploitRelease NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 16.0.6345 (включая) до 16.3.6985 (исключая)
cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:*
EPSS
Процентиль: 99%
0.8308
Высокий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-502
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.
EPSS
Процентиль: 99%
0.8308
Высокий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-502